GCP Professional Cloud Security Engineer Practice Question

Your company operates an on-premises data center that must exchange traffic with a Google Cloud VPC over two redundant VPN tunnels. The networking team wants to eliminate the manual effort of updating static routes every time a new subnet is added either on-premises or in Google Cloud, and they need the link to provide a 99.99 percent availability SLA. What should you do to meet these requirements?

  • Keep the existing tunnels but enable route export on the VPC and use Cloud NAT to propagate new internal prefixes to the on-premises router automatically.

  • Deploy an HA VPN gateway and attach a Cloud Router with BGP sessions on each tunnel interface so route advertisements between the VPC and the on-premises router occur automatically.

  • Migrate the connection to Dedicated Interconnect and create custom static routes on a Cloud Router to advertise VPC subnets while disabling BGP on the on-premises router.

  • Replace the VPN with two policy-based VPN tunnels that use IKEv2 and configure static routes for every current and future subnet on both sides.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot